Document: draft-ietf-spring-srv6-security
Title: Segment Routing IPv6 Security Considerations
Reviewer: Henning Rogge
Review result: Has Nits

Hello, I was asked to do a review of draft-ietf-spring-srv6-security-16 by the
rtg-dir.

At first, I really like the extended Terminology section of this draft, this
makes the document more precise which is especially important for security
documents.

Section 4 Nit:
I am not sure MACsec needs to be discussed here, its a fully authenticaed and
encrypted layer-2 connection as far as I know... which would mean an attacker
without the key cannot even read the IP bytestream. If MACsec is used to secure
the trusted domain it needs to be done for all layer-2 links in the domain,
including the one to/from/between routers that do not process the SRH. Nothing
special in regards to SR.

General Nit:
RFC 8986 already states that using IPv6 Authentication Headers (AH) is not
applicable for SR deployments. Should this document mention any kind of
interaction with Encapsulating Security Payload (ESP) header? Or are there just
no interactions or are they out of scope of this document?

I think the document does a good job discussing the security aspects of Segment
Routing. I don't follow the Spring WG mailing list, so if these two nits have
already be discussed I would consider the document Ready.

Henning Rogge
Fraunhofer FKIE - Germany


_______________________________________________
spring mailing list -- [email protected]
To unsubscribe send an email to [email protected]

Reply via email to